Cookie Policy

Last updated: July 24, 2026. Your browser controls can clear site data, but doing so may sign you out or remove local preferences.

Authentication

Secure HttpOnly SameSite cookies maintain a signed-in or short-lived recovery session. They do not contain passwords or recovery codes.

Security

Rate limiting, CSRF/origin validation, passkey challenges, and trusted-session protections may use short-lived server or browser state.

Preferences

Theme and your cookie-consent choice are stored in browser localStorage (the `theme` and `cookie-consent` keys); workspace layout and guest session choices may also be stored locally.

Analytics

Google Analytics 4 measures aggregate usage and sets its cookies only under Consent Mode v2 — analytics and advertising signals default to denied in the EEA, UK, and Switzerland until you accept in the consent banner, and your saved choice is reapplied on return visits. First-party Vercel Web Analytics and Speed Insights measure page and interaction performance without advertising cookies.

Advertising

Marketing routes may show ads from Adsterra and Infolinks; Google AdSense verification assets remain in place while a re-application is pending. These vendors may set their own cookies under their policies, according to your consent. Classic, Studio, account, admin, and other authoring/security routes are ad-free.

Project data

Signed-in projects are stored in Turso, not cookies. Private assets use Vercel Blob. Guest work is stored device-locally in your browser using IndexedDB and can be exported as `.novusvis`; clearing site data removes it.